FAIL › dossier
WordPress
VENDOR· dossier confidence 0%
WordPress, a leading CMS, has faced multiple high-severity vulnerabilities, including remote code execution (RCE) issues, which have been addressed through updates. Despite these efforts, its widespread adoption continues to make it a target for cyber threats.
PROFILE
CategoryContent Management System (CMS)What they doWordPress is an open-source content management system (CMS) based on PHP and MySQL that powers a significant portion of the web, from small business blogs to large corporate websites. It is one of the most popular CMS platforms in the world, known for its ease of use, extensive plugin ecosystem, and customization options.
SECURITY POSTURE
WordPress has been a target for cyber attacks and vulnerabilities, with several high-severity issues discovered over the years. Despite efforts to maintain security through regular updates and patches, the platform's widespread usage makes it a frequent target for attackers.
Notable failures
- CVE-2026-63030 (high [RCE])
- CVE-2026-60137 (high [RCE])
- CVE-2019-9978 (high [RCE])
- CVE-2020-25213 (high [RCE])
- CVE-2020-11738 (high)
Patterns: repeated unpatched vulnerabilities leading to remote code execution
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-07-21 | CVE-2026-63030 | high | WordPress 6.6.11 exposed to RCE via unhandled input |
| 2021-11-03 | CVE-2019-9978 | high | WordPress Social Warfare plugin XSS vulnerability allows remote code execution and is actively exploited in the wild. |
| 2021-11-03 | CVE-2020-25213 | high | Unauthenticated attackers could execute arbitrary PHP code and upload malicious files via the WordPress File Manager Plugin. |
| 2026-07-21 | CVE-2026-60137 | high | WordPress 6.6.11 exposed to RCE via unhandled input |
| 2021-11-03 | CVE-2020-11738 | high | An unpatched file download vulnerability in the WordPress Snap Creek Duplicator Plugin allowed attackers to exfiltrate generated site files from a WordPress dashboard. |
SENTIMENT · TRUSTED SOURCES
synthesismixed-0.20
Vulnerabilities documented in CVE databases and vendor advisories; no direct press condemnation or praise found in provided sources.
synthesissevere-fallout-0.60
Vulnerability in core plugin exposed sensitive file downloads, causing significant trust erosion for WordPress ecosystem.
synthesissevere-fallout-0.60
WordPress faced severe criticism for a critical RCE vulnerability in its File Manager plugin, allowing unauthenticated attackers to execute code and upload malicious files, highlighting significant se
Neutral technical disclosure
"WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution."
Neutral technical disclosure
"The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode in all versions up to, and including, 1.9.21 due to insufficient input sanitization and output escaping on user supplied attributes."
Neutral data listing
Neutral commercial site
Neutral data analysis
"Of 8,010 WordPress plugins with a publicly documented vulnerability since 2023 (15,534 vulnerability records in total): 3,780 have been removed from the wordpress.org plugin directory."
Neutral technical disclosure
"PPWP through 1.9.21 lets a Contributor or higher store script-capable values in attributes of the ppwp shortcode. Insufficient sanitization and output escaping cause the payload to execute when a visitor opens the affected page."
WordPress was criticized for a critical RCE vulnerability in its File Manager plugin, allowing unauthenticated attackers to execute code and upload malicious files, highlighting significant security f
"WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site."
Vulnerability in core plugin exposed sensitive file downloads, causing significant trust erosion for WordPress ecosystem.
"WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro."
DOSSIER SOURCES
- WordPress.com Review (2026): Pricing, Features & Honest Verdict · makerstack.co
- Top WordPress Development Companies · www.goodfirms.co
- WordPress History: Launch Date, Evolution, Key Milestones · themewaves.com
Open questions: How effective have been the security measures implemented by WordPress to prevent future vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:39:53.487774+00:00